[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH 1/2] tools/symbols: reject names exceeding the runtime limit


  • To: xen-devel@xxxxxxxxxxxxxxxxxxxx
  • From: Mykola Kvach <mykola_kvach@xxxxxxxx>
  • Date: Wed, 7 Oct 2026 21:11:02 +0300
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=KJ/SWrGIpUv/PLRbu/p6/k51GXDlaNdmbUFmS03sfGo=; b=Ydnax2fSyFb6nhjX1leLzRUo666C7y3dYNw9gEJJE68kZLO63ly7FOjIn1RVo8VUX3rbzboHpS4v/AlIQh2kH1QUO5/wftJYmt0e0rA09piuJ8rs2fisLPRZoH8y81zUtUbYseWs1cyBC0VeXc00N4dZ0tGUaWXpZUs0zaRtHq4noe+lbEMdCjlnxEeyAo7sE5vPOc1CDfQ4vZ57qzFa70yG678085qYlI45jnPZvAl73FEVHbfiWexS0GnRjeKccj+mB9UgF9MKF3CLjozPuGuWtV6Tkwwf+Va2CKCWaax1g+TNrjjDuwA13hPAULB+mdRvs3Y+iPbSnVYg0ClzFQ==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=PbBfH6jY8/4fr0pyCcc5K9En9PqUd/eft9GL01ElB4JPDW2wCaAXL0gE5ajmeCoEo1TJ8d7zMKaoyzbbl3564gpFUqHCvMj4AJFMtxsxOxYDpi5CjJMm0VtYfph3A16HIX4UdgL7BLlwpd2RAMxWhN5YzRw37036uUqjnjLvaDYi32sOquDJpFUQOEBDq8HUfGxW3AVnOnkbbzfozc+Eg313oBEoiFQoX8PRyQPFs2MjCyBZGfKm0jZgzp3GHHOmP1dh+G8l8rPiFIdr6WDSQoU9RpBib7TM2Z1S0X3xklSdJMCXugf3JUEm2AdexsHU3XNwHtmqbXkYxNeTYNpLxQ==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=epam.com header.i="@epam.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: mx.microsoft.com 1; dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com;
  • Cc: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Anthony PERARD <anthony.perard@xxxxxxxxxx>, Michal Orzel <michal.orzel@xxxxxxx>, Jan Beulich <jbeulich@xxxxxxxx>, Julien Grall <julien@xxxxxxx>, Roger Pau Monné <roger@xxxxxxxxxxxxxx>, Stefano Stabellini <sstabellini@xxxxxxxxxx>
  • Delivery-date: Wed, 07 Oct 2026 18:11:23 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

The symbol generator accepts names longer than the runtime lookup
buffers, which hold KSYM_NAME_LEN + 1 bytes. SYSV input prefixes local
symbols with their filename, so an absolute assembly source path can
produce an oversized name even when the symbol itself is short.

This caused a debug Xen boot to crash on an Orange Pi 5. The expanded
name ending in mmu/head.S#identity_mapping_removed was 145 bytes long.
During the test_symbols() constructor (CONFIG_SELF_TESTS),
symbols_lookup_by_name() expanded it into a 128-byte buffer and
overwrote the saved frame pointer and return address.

The board reported:

  (XEN) [    5.064767] Hypervisor Trap. HSR=0x0000008a000000 EC=0x22 IL=1 
Syndrome=0x0
  (XEN) [    5.066709] PC:     65766f6d65725f67 65766f6d65725f67
  (XEN) [    5.067190] LR:     65766f6d65725f67
  (XEN) [    5.074749]     X27: 0000000000000000 X28: 0000000049000000  FP: 
6e697070616d5f79

The FP and LR values decode to "y_mappin" and "g_remove", respectively,
matching bytes 128 through 143 of the expanded name.

Reject retained names exceeding the existing KSYM_NAME_LEN limit before
compression. Report the offending name and its byte length, so that the
build fails with, for example (name shortened here)::

  Symbol '...#compatibility_mode' is too long (128 bytes, maximum 127)

A build from a very long absolute source path now stops at link time,
instead of producing an image with a latent overflow. Apply the check
after symbol filtering and preserve unrestricted human-readable
--xensyms maps.

Fixes: d37d63d4b548 ("symbols: prefix static symbols with their source file 
names")
Assisted-by: Codex:GPT-6.1
Assisted-by: Copilot:claude-sonnet-5.5 # host and x86 build tests
Signed-off-by: Mykola Kvach <mykola_kvach@xxxxxxxx>
---
 xen/tools/symbols.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/xen/tools/symbols.c b/xen/tools/symbols.c
index 9db1c0a20c..e15273a8ad 100644
--- a/xen/tools/symbols.c
+++ b/xen/tools/symbols.c
@@ -485,6 +485,13 @@ static void build_initial_tok_table(void)
        pos = 0;
        for (i = 0; i < table_cnt; i++) {
                if ( symbol_valid(&table[i]) ) {
+                       if (!map_only && table[i].len > KSYM_NAME_LEN + 1) {
+                               fprintf(stderr,
+                                       "Symbol '%s' is too long (%u bytes, 
maximum %u)\n",
+                                       SYMBOL_NAME(&table[i]), table[i].len - 
1,
+                                       KSYM_NAME_LEN);
+                               exit(1);
+                       }
                        if (pos != i)
                                table[pos] = table[i];
                        learn_symbol(table[pos].sym, table[pos].len);
-- 
2.53.0




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.